A path-traversal flaw was found in gvproxy (gvisor-tap-vsock) in the port-forwarder's /services/forwarder/expose REST endpoint. When invoked with protocol=unix, the caller-supplied local field was passed without any validation to os.Remove() followed by net.Listen("unix", ...) on the host filesystem. Because this endpoint is exposed unauthenticated on the VM gateway (192.168.127.1:80), a process inside the guest VM — including an unprivileged container — could send a single HTTP POST to delete an arbitrary file owned by the gvproxy user on the host and replace it with a unix-socket inode. This crosses the container/VM-to-host isolation boundary, allowing destruction of sensitive host files (SSH keys, kubeconfig, shell/registry configuration) and denial of service. The issue was fixed by removing the os.Remove() call so pre-existing files can no longer be deleted or overwritten.